Reduced audit preparation effort
The evidence an auditor asks for is already attached to each finding. Preparation becomes assembling what exists, not reconstructing a year.
Ward Agent reads your Microsoft 365 or Google Workspace security settings on a schedule, checks them against the HIPAA Security Rule, and turns drift into findings SaberGuard's compliance team reviews before you hear about them. Nothing to install. No portal.
Ward Agent
collect · normalize · evaluate
Practice systems · covered through the attestation and business associate review
Read-only configuration inchecked against the Security Rulereviewed by SaberGuard's compliance teamyour signed report
Never read: email content, files, calendars, chat, or patient records. Your administrator can revoke access at any time.
Reads security settings only: MFA state, admin roles, sharing, device compliance, audit settings. Never email, files, calendars, chat, or patient records.
Your administrator · 15 minutes
Your admin grants Ward a read-only, configuration-only connection. One isolated credential, revocable at any time.
Scoped read-only accessAutomated · on a schedule
Security settings become plain facts: who has MFA, who holds admin rights, how sharing is set, whether devices are managed.
Timestamped, hashed evidenceRules engine · not an AI
Each fact is checked against hand-written rules mapped to the Security Rule. A rule, not an AI, decides whether a control is met.
Candidate findings with citationsJonathan DeLeon, CISM®
A person reads every candidate finding, rejects what doesn't hold up, and signs what does. You receive the report and summary.
Signed findings and executive summaryYour baseline risk analysis, running on a schedule instead of once a year.
Collection runs on a schedule, not once a year. A new admin account or a disabled MFA policy becomes a finding within days.
Every observation is timestamped, hashed, and archived immutably. When an auditor asks how you know, the evidence is already there.
Which controls are met, which have gaps, and what changed since last time, by safeguard family.
Findings arrive ordered by severity with the fix attached. Drift gets caught and closed while it is still small.
A plain-language summary on your schedule: what changed, what was fixed, what is open. Written for owners, signed by the reviewer.
Compliance status, risk findings, the monitoring timeline, and the executive summary that lands in your inbox.
Ward Agent · reviewer console · sample data
Overall
9 gaps across 44 evaluated controls
Baseline Jun 2026 · 23 gaps
Open findings
9
↓ from 23
Evidence items
312
timestamped
Next collection
Mon 06:00
scheduled
Illustrative sample. SaberGuard reviews this console; you receive the signed report and executive summary. There is no client login.
Read-only, limited to security settings, revocable by your administrator at any time.
What Ward reads
What Ward never reads
No portal, no client login, no software to install. You receive the report; SaberGuard runs the tool.
Every finding points at the configuration that produced it, when it was observed, and the rule that fired.
The evidence an auditor asks for is already attached to each finding. Preparation becomes assembling what exists, not reconstructing a year.
A risk analysis is a photograph; your practice keeps moving. Monitoring keeps the signed report true between annual refreshes.
Owners get the three numbers that matter and what changed. Boards, insurers, and hospital partners get something they can read.
Gaps get closed while they are small. Over a year the open-finding count goes down and stays down, with dates to prove it.
Each practice gets its own isolated credential. Your administrator can revoke it at any time.
Collected configuration is hashed and stored immutably. Review history cannot be edited after the fact.
Ward never requests, receives, or stores patient records or anything a patient wrote. Hosted in Microsoft Azure.
Monitoring starts after a baseline risk analysis. The scoping call covers both.
SaberGuard assesses and advises; it does not warrant compliance.